Virtual Machine Isolation for Encrypted Virus Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virus detection methods, such as signature scanning and emulation, are inadequate in detecting randomly encrypted and polymorphic viruses, leading to incomplete protection against malicious code, and require resource-intensive processes and frequent updates.

Innovation Solution

A method and system utilizing virtual machines for secure network access, where a virtual machine is provisioned to analyze content, detect viruses, and isolate potential threats, decoupling client risk and allowing centralized antivirus management, enabling anonymous network access and controlled access policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature scanning is used to detect viruses, then detection capability is improved, but resource consumption increases and detection precision deteriorates against encrypted viruses

Engineering Contradiction:
Improvevirus detection capabilityVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the scanning process into two distinct phases: an initial fast scan using virus signatures on file headers and known patterns, and a subsequent emulation scan on suspicious sections. This segmentation allows the system to maintain low resource consumption during routine scanning while allocating resources intensively only when needed, resolving the contradiction between detection capability and resource usage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary emulation environment that acts as a mediator between the file system and the virus detection engine. This intermediary layer executes suspicious code in a controlled virtual environment, allowing detection of encrypted and polymorphic viruses without requiring resource-intensive scanning of entire files, thus improving detection precision while managing resource consumption.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If emulation is used to detect encrypted viruses, then detection precision is improved, but viruses may execute before detection causing infection

Engineering Contradiction:
Improveencrypted virus detection accuracyVSAvoidtime for virus execution before detection
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by performing fast signature-based scanning on file headers and known patterns before initiating emulation. This preliminary detection phase identifies obviously malicious files and suspicious sections that require emulation, allowing the system to prepare and control the emulation process before the virus can execute, thus preventing infection while maintaining high detection precision.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements preliminary anti-action by establishing a controlled emulation environment with pre-configured security measures before executing suspicious code. The emulation sandbox is prepared in advance with restricted system access and monitoring capabilities, preventing viruses from executing harmful actions even if they decrypt themselves during emulation, thereby counteracting the potential harm before it occurs.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If comprehensive virus scanning is performed, then protection coverage is improved, but system resources are excessively consumed

Engineering Contradiction:
Improveprotection coverageVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by performing comprehensive virus scanning only on suspicious file sections identified during the initial fast scan, rather than scanning entire files. The emulation process focuses specifically on questionable code segments, maintaining high protection coverage while significantly reducing system resource consumption compared to exhaustive scanning of all files.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If emulators are used for virus detection, then detection capability is improved, but viruses may become aware of emulators and avoid detection

Engineering Contradiction:
Improvevirus detection capabilityVSAvoidvirus evasion capability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies parameter changes by dynamically modifying emulation parameters such as execution timing, memory allocation, and system interface behavior. By varying these parameters across multiple emulation attempts, the system can detect viruses that attempt to identify static emulation environments, maintaining detection capability against adaptive viruses while preserving the benefits of emulation-based detection.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS8881284B1Method and system for secure network access using a virtual machine
Publication Date: 2014.11.04 CA TECH INC
  • US8881284B1 patent drawing
  • US8881284B1 patent drawing
  • US8881284B1 patent drawing

AI summary

A method and apparatus for secure network access using a virtual machine are disclosed. The method includes provisioning a virtual machine, downloading content to the virtual machine, and sending information from the virtual machine. The information that is sent from the virtual machine is configured to allow the display of output from the virtual machine. The output from the virtual machine is based on the content. The apparatus includes a number of virtual machine servers. Each of the virtual machine servers is configured to support at least one of a number of virtual machines. A first virtual machine of the virtual machines includes an antivirus module. The first virtual machine is configured to download content. The antivirus module is configured to detect a virus by virtue of being configured to analyze the content.